|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 56
Members: 0
Total: 56
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
got into PhpMyadmin but no privileges ... please help! |
|
Posted: Wed Jan 21, 2009 12:33 am |
|
|
k40t1x |
Regular user |
|
|
Joined: Dec 27, 2008 |
Posts: 22 |
|
|
|
|
|
|
|
The admin forgot to restrict access, so everybody can gain access to PhpMyadmin with any username and without pass but with no privilege. I can just access the Information_schema Table and execute Select statements. The version of this PhpMyadmin is 2.11.8.1. Any Ideas? The website has also a Vbulletin 3.7.4 Forum ... |
|
|
|
|
Posted: Wed Jan 21, 2009 1:02 am |
|
|
k40t1x |
Regular user |
|
|
Joined: Dec 27, 2008 |
Posts: 22 |
|
|
|
|
|
|
|
I also found an XSS vulnerability but still need help ... |
|
|
|
|
Posted: Wed Jan 21, 2009 1:28 am |
|
|
one23 |
Advanced user |
|
|
Joined: Dec 12, 2008 |
Posts: 98 |
|
|
|
|
|
|
|
do you you access to the vb forum's db ?
if yeah , you're lucky ... |
|
|
|
|
Posted: Wed Jan 21, 2009 1:36 am |
|
|
k40t1x |
Regular user |
|
|
Joined: Dec 27, 2008 |
Posts: 22 |
|
|
|
|
|
|
|
of course not :p just to Information_schema table |
|
|
|
|
Posted: Wed Jan 21, 2009 2:39 am |
|
|
k40t1x |
Regular user |
|
|
Joined: Dec 27, 2008 |
Posts: 22 |
|
|
|
|
|
|
|
|
|
|
|
www.waraxe.us Forum Index -> Newbies corner
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|